Junglewise Threat Intelligence

CVE-2015-1130: Apple OS X Authentication Bypass Vulnerability

CVE-2015-1130 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-02-10

Vendors: Apple.

Executive brief

The XPC implementation in the Admin Framework in Apple OS X allows local users to bypass authentication and gain administrative privileges. This vulnerability stems from unspecified vectors within the framework's handling of inter-process communication.

Affected products

  • Apple OS X before 10.10.3

Timeline

  • 2015-04-08: patched: Apple released OS X 10.10.3 to address the issue.
  • 2022-02-10: kev added: CISA added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog.

Related threats